Is there a list somewhere of the actual Root CA certificates that will be removed as part of this? Is it just any Root CA certificate that has "Symantec, Thawte, VeriSign, Equifax, GeoTrust, and RapidSSL" in it's name?
I think this is what you're looking for: https://chromium.googlesource.com/chromium/src/+/master/net/...
Chrome's Plan to Distrust Symantec Certificates
81–90 of 207 posts
Re: Chrome's Plan to Distrust Symantec Certificates
#82Earlier quoted context omitted.
It's useful for no-name companies, an EV certificate highlights a company that went through unnecessary pain just to get a little green checkbox - I know I personally trust smaller online retailers more when they have one since they've had to prove their identity to a CA. Nobody notices the lack of EV on amazon.com, because, well, it's Amazon.
> Nobody notices the lack of EV on amazon.com, because, well, it's Amazon. Which means that nobody notices the lack of EV on amazoone.com, because, well, it'as Amazon.
Re: Chrome's Plan to Distrust Symantec Certificates
#83Earlier quoted context omitted.
Considering that literally anyone who gets even local access to any server at all, or can spoof one - even servers that have never used LetsEncrypt before - can generate new valid LetsEncrypt certificates, and nothing generated has a password on it, I don't know if I would consider them trustworthy. If you want to passively monitor encrypted traffic on a massive scale and not get caught (other than via their log - an…
I think it's a valid criticism, not LE but industry as a whole. Intel should add usable HSM in every cheap laptop, not even talking about servers instead of their ME backdoors. Technology is there, it's cheap and it's needed.
TPMs generally aren't fast enough to do RSA signatures a on busy webserver though, but they're wonderful for protecting VPN certificates (tools for managing this are built into windows Group Policy, I imagine it's very painful on Linux)
Re: Chrome's Plan to Distrust Symantec Certificates
#84What are some trustable providers of EV certificates? LetsEncrypt is wonderful, but if I'm a company that needs to show the company name next to the padlock, who should I be using? What's an easy way to check if a provider (for instance Gandi, who I use for my domains) is going to be culled by this? In fact, I don't even seem to able to find certificate information in Chrome any more - clicking on the padlock just gi…
Sorry, what's a company that needs to show the company name beside the padlock? (Except maybe: Company that has too much money to spend on pointless "premium" security services without any shown benefit.)
Re: Chrome's Plan to Distrust Symantec Certificates
#85What are some trustable providers of EV certificates? LetsEncrypt is wonderful, but if I'm a company that needs to show the company name next to the padlock, who should I be using? What's an easy way to check if a provider (for instance Gandi, who I use for my domains) is going to be culled by this? In fact, I don't even seem to able to find certificate information in Chrome any more - clicking on the padlock just gi…
> I'm a company that needs to show the company name next to the padlock Does anyone actually look at or care about that?
Re: Chrome's Plan to Distrust Symantec Certificates
#86I wish browser vendors would let me choose a trusted entity and make it simple for me to trust only CAs that my trusted entity supports, or the intersection of what multiple trusted entities endorse. The incentive for a mass-market browser is to trust pretty much everything, but I'd prefer to use a browser that is a bit more paranoid. If a website can't load properly because I don't trust one or more of the CAs, I mi…
I cannot read Mandarin or Turkish, and in the unlikely event I get forwarded to a site from a company targeting citizens from these countries, I'd prefer to just get an SSL exception instead of the 'trusted' page.
Re: Chrome's Plan to Distrust Symantec Certificates
#87"including Thawte, VeriSign, Equifax, GeoTrust, and RapidSSL" RIP RapidSSL wildcard
Wow, I never realised VeriSign was a Symantec brand. I'm not sure what it says that Google doesn't trust the company that operates the registry for .com
Re: Chrome's Plan to Distrust Symantec Certificates
#88What are some trustable providers of EV certificates? LetsEncrypt is wonderful, but if I'm a company that needs to show the company name next to the padlock, who should I be using? What's an easy way to check if a provider (for instance Gandi, who I use for my domains) is going to be culled by this? In fact, I don't even seem to able to find certificate information in Chrome any more - clicking on the padlock just gi…
> LetsEncrypt is wonderful, but if I'm a company that needs to show the company name next to the padlock, who should I be using? Sorry, what's a company that needs to show the company name beside the padlock? (Except maybe: Company that has too much money to spend on pointless "premium" security services without any shown benefit.)
For example, I can go grab something like "bannk.com" (notice two 'n's) and get a DV cert for it - because I hypothetically own that name. Now, I can copy the real "bank.com" onto the site and perform a phishing attack. They both appear to be encrypted but the EV'd one has the organization noted, the fake one will not be able to have that legitimacy.
I am not saying the system isn't without its faults (people might not even notice), but it's an extra measure a company can do to keep itself distinguished from phshing websites or copycat services.
Re: Chrome's Plan to Distrust Symantec Certificates
#89What are some trustable providers of EV certificates? LetsEncrypt is wonderful, but if I'm a company that needs to show the company name next to the padlock, who should I be using? What's an easy way to check if a provider (for instance Gandi, who I use for my domains) is going to be culled by this? In fact, I don't even seem to able to find certificate information in Chrome any more - clicking on the padlock just gi…
> LetsEncrypt is wonderful, but if I'm a company that needs to show the company name next to the padlock, who should I be using? Sorry, what's a company that needs to show the company name beside the padlock? (Except maybe: Company that has too much money to spend on pointless "premium" security services without any shown benefit.)
on the contrary, I know that the presence of an EV line has helped my mother avoid a pretty decent phishing attempt. Any company holding confidential details or data should have one, its just a shame they are so expensive (which due to their verification is unlikely to come down too far).
Re: Chrome's Plan to Distrust Symantec Certificates
#90I wish browser vendors would let me choose a trusted entity and make it simple for me to trust only CAs that my trusted entity supports, or the intersection of what multiple trusted entities endorse. The incentive for a mass-market browser is to trust pretty much everything, but I'd prefer to use a browser that is a bit more paranoid. If a website can't load properly because I don't trust one or more of the CAs, I mi…
Exactly. I've never understood why all the US / EU language versions of Chrome, Firefox, etc. include all the root certs for CAs from China, Turkey, Russia, etc. I cannot read Mandarin or Turkish, and in the unlikely event I get forwarded to a site from a company targeting citizens from these countries, I'd prefer to just get an SSL exception instead of the 'trusted' page.
That just makes the normal user who wants to buy stuff learn to ignore SSL errors.